Security update, wp-cache 2.1.1
I just released WP-Cache Version 2.1.1. It contains a security fix from Alex Concha to avoid CSRF attacks directed to admin pages which can inject wrong values into the configuration form, which can allow XSS attacks if those fake values are saved into the configuration file.
To update just uncompress the zip file from plugins’ directory (and overwrite older files).
Warning: this version uses control functions only available in Wordpress >= 2.0. It won’t work with previous WP versions.
BTW: I’m very busy and going worse, I’ll be more than happy if someone else takes care of WP-Cache.
Actualización de Wp-cache a la versión 2.1.1
Me he enterado por el blog de Ricardo Galli que ha actualizado su famoso plugin para wordpress wp-cache que soluciona unos problemas de seguridad de la versión anterior. El fallo de seguridad a sido arreglado por Alex Concha y esta nueva versión del wp…
Trackback by meneame.net — Saturday 24/3/2007 @ 11:44
Ricardo Galli: Thanks so much for working on this. This plugin is great, and practically a necessity these days.
Everyone else: If you’ve been having problems with symbolic links, I’ve update my version of wp-cache with the above security fix that allows you to still use the plugin. You can find it at http://twentythree7.com/wp-cache-nosymlink
Comment by Brandon — Saturday 24/3/2007 @ 20:36
I’ve sent an email about wp-cache localization to gallir[at]uib.es.
looking forward to hearing from you, thanks.
Comment by SilverFox — Tuesday 3/4/2007 @ 17:29
Hello,
When I installed this plugin and went to the Options tab, I received the following message:
Fatal error: Call to undefined function: wp_verify_nonce() in /wp-content/plugins/wp-cache/wp-cache.php on line 182
Could you please tell me if there’s something else I need to do with this? I couldn’t find any mention of it in your FAQ or other comments.
Many, many thanks in advance for any assistance you can provide. I’m sure you’re very busy and have trouble providing full support for this…
Comment by Dustin LindenSmith — Tuesday 3/4/2007 @ 21:43
#4, you don’t have last WP version, do you?
Comment by gallir — Tuesday 3/4/2007 @ 21:45
[…] Galli has released, today, a security update for his popular plugin, WP-Cache 2: “It contains a security fix from Alex Concha to avoid […]
Pingback by twentythree7 » Security Update, WP-Cache NoSymlink 2.1.1 — Wednesday 4/4/2007 @ 11:28
Re #4, I’m running 2.0.2.
Comment by Dustin LindenSmith — Wednesday 4/4/2007 @ 13:40
Ricardo, me parece que esas funciones fueron añadidas a partir de la versión 2.0.3; una alternativa sería usar check_admin_referer en lugar de wp_nonce_field/wp_verify_nonce o incluir estas funciones dentro del plugin.
Comment by alex — Wednesday 4/4/2007 @ 15:34
[…] Ricardo Galli, de software libre » Security update, wp-cache 2.1.1 (tags: security wordpress) […]
Pingback by ArtLung Blog » Daily Links — Saturday 7/4/2007 @ 9:21
[…] to cache, and I decided to finally try it with this site. I have heard many good things about the WP-Cache plugin and got it installed today. If you notice a difference in load times over the course of the […]
Pingback by Jennifer Zelazny: giving wp-cache a try. — Wednesday 11/4/2007 @ 23:44
[…] de wp-cache, que tiene un problema similar a Adsense-Deluxe. Pueden actualizar manualmente a la versión 2.1.1 para corregir este […]
Pingback by Wordpress: Lista de plugins no recomendados - Buayacorp — Tuesday 17/4/2007 @ 14:33
I have a weird problem with WP-Cache. I’ve installed it yesterday and everything seemed to work fine. But there is a small problem with WP-Cache under Internet Explorer. When someone leaves a comment, like I do here, the ‘Name’-field doesn’t remeber your name anymore, when the plugin is activated. The name (and e-mail or website) of someone who posted a comment before appears. Could someone explain how that is possible?
Comment by Mira — Saturday 21/4/2007 @ 12:16
I get the following error when WP-Cache is enabled, and only when it’s enabled:
“Internal Server Error
The server encountered an internal error or misconfiguration and was unable to complete your request.
Please contact the server administrator, support@supportwebsite.com and inform them of the time the error occurred, and anything you might have done that may have caused the error.
More information about this error may be available in the server error log.
Apache/1.3.33 Server at www.bittbox.com Port 80″
I have my wp-content folder writable by the server, but I’m a graphic designer. Plz Help! I would really love to use this plug-in.
(I have an .htaccess file in wp-content that prevents hotlinking if that has anything to do with my error?)
Comment by BittBox — Saturday 21/4/2007 @ 22:21
I get the same internal server error as BittBox when I enable the caching, but without a .htaccess file in the wp-content folder.
Because your error is identical to mine (including the invalid email address in the error message), I need to ask - do you use GoDaddy web hosting?
Comment by Wacka — Thursday 26/4/2007 @ 0:02
Yes. I sure do. But they don’t seem to want to admit it’s their problem or provide help on this matter
Comment by BittBox — Thursday 26/4/2007 @ 2:00
Cache isn’t updated when creating a new link on the blogroll.
Comment by Joaquin — Thursday 26/4/2007 @ 3:41
hi,
i installed wp-cache V2.1.1 on WP V2.1. it says that i should disable gzip compression on the Options/Miscellaneous page.
Problem: THERE IS NO GZIP COMPRESSION SWITCH IN MY WP, ANYWHERE !!
How do I disable it (at the PHP level) ? I am on a hosted server and have no access to the conf, their client service is unresponsive. Thanks for any help.
Comment by rd — Friday 27/4/2007 @ 12:42
You can find the setting for GZIP compression in the admin part of WordPress, under Options >> Reading. It’s a checkbox setting with the label, “WordPress should compress articles (gzip) if browsers ask for them”
Comment by Wacka — Friday 27/4/2007 @ 16:10
Just a suggestion … can the time limit for cache expiry be replaced with some thing like until a new post/page/comment is published on the blog.
I think until a post/page/comment is created/deleted/updated there is no need to expire the cache. This may help speed up the wordpress blogsphere even more.
Comment by S Jain — Friday 27/4/2007 @ 17:31
Hi Ricardo and all.
Plugin installed on BLuehost Server hosting with WP 2.0.5 is working fine. No error on install…it seems it generted well cached pages and our site (www.planet-sansfil.com) seems working faster. Just one question Ricardo : Does the plugins decrease the CPU Process ? I mean like the page is stored there are not so much access to the DB and then should put down the CPU Request ??!!
Thanks anyway for the job.
Comment by Planet Wifi — Monday 30/4/2007 @ 12:09
#20, yes, it does reduce –a lot– the cpu load.
Comment by gallir — Monday 30/4/2007 @ 12:12
Thank you so much for a useful plug-in. My web host recommended downloading it as they work to resolve some MySql issues. I have been monitoring my site closely and it is performing just as well as I hoped that it would.
Comment by Matt Keegan — Wednesday 2/5/2007 @ 20:13
Worked just great at my site! Thanks for this nice plugin!
Comment by Max Thrane — Friday 4/5/2007 @ 0:46
[…] WP-Cache ein fallweise sehr nützliches Plugin, das bei hohem Trafficaufkommen die Datenbankzugriffe weitestgehend minimiert, indem automatisch statische HTML-Seiten generiert werden, statt den Blogartikel dynamisch bei jedem erneuten Leserzugriff zusammenzustellen (man spart sich damit das Interpretieren der PHP-Templateanweisungen, das Auslesen der Artikeltexte und Kommentare aus der Datenbank, ebenso die restlichen Parameter wie etwa Kategorien, Tags, etcpp). Was zusätzlich hilft, ist das wahlweise Umschalten auf ein sehr grafikarmes, aber auch sehr schlichtes Template, um die Zahl der http-requests zu minimieren. […]
Pingback by Basic Thinking Blog » Wordpress-Plugins: Blog-Carnival — Monday 7/5/2007 @ 1:49
[…] WP-Cache: Cashfunktion für Wordpress vorgestellt von Basic Thinking […]
Pingback by Geordnete Liste aller im Blog Karneval vorgestellten Wordpressplugins » Artikel » NSAHs Blog — Tuesday 8/5/2007 @ 2:32
I’m getting the “blank display when loading an uncached page” problem.
Last year’s “change ob_end_clean() to ob_end_flush()” isn’t useful because the call to ob_end_clean() is no longer in the code.
Comment by billg — Thursday 10/5/2007 @ 0:55
I’ve got the same problem.
Comment by DenisO — Monday 14/5/2007 @ 4:03
Este plugin falla más que una escopeta de feria. Vaya desastre.
Comment by fallo — Monday 14/5/2007 @ 13:02
[…] is reinforced by the author’s decision to suspend its future development (according to his wp-cache 2.1.1 article), due to time constraints. This was written by sairuh. Posted on Thursday, 17 May 2007, at 3:33 […]
Pingback by Iwaruna.com » Upgrading to WordPress 2.2 — Friday 18/5/2007 @ 1:33
That’s too bad about the news on suspending development for wp-cache. I’m new to WP and read a lot of good things about it. My only problem with it is that I had to constantly clear the cache when I made updates to pages and such. Otherwise it did make a difference is performance.
Comment by Rolando — Saturday 19/5/2007 @ 7:15
[…] WP-Cache 2.1.1 and More When I originally downloaded WP-Cache from the plugin page for WP Cache 2, the download was for version 2.0.17. I stopped by several times over the course of the last few months and never noticed anything different. That’s because I didn’t scroll down and see the notes that were posted in the “downloading” area. I found out there’s a much newer version available for download from that page and some notes about it at Security update, wp-cache 2.1.1. […]
Pingback by WP-Cache 2.1.1 and More - Untwisted Vortex - Living in a Different Land — Saturday 19/5/2007 @ 19:10
[…] | Admin Drop Down Menu | Admin Drop Menus | Barunio Administration | Batch Categories | Cache | Category Manager | CJD-Spam Nuke | Cron | Dashnote | Delete Comment IP immediately | Enhanced […]
Pingback by Die beliebtesten WordPress-Plugins in der deutschsprachigen Blogosphäre — Software Guide — Wednesday 23/5/2007 @ 0:21
[…] WP-Cache : Protects the web server from high-volume page views. This is a life-saver if a site is featured […]
Pingback by Colin Meeks » Wordpress Workhorse — Tuesday 5/6/2007 @ 18:41
[…] just installed wp-cache 2.1.1, a plugin for Wordpress that caches dynamically generated pages as static files. All future […]
Pingback by Using Caching | iface thoughts — Friday 15/6/2007 @ 11:37
谢谢!很有用的一个插件,我用了很久了,并且一直在用。
Comment by oline — Friday 15/6/2007 @ 12:20
I know you aren’t actively maintaining the plugin right now, but I came up with a fix for the Content-Type of feeds when using WP-Cache2. You can get the diff here:
http://dougal.gunters.org/projects/wp-cache2/wp-cache-phase2.php.diff
The first part of the patch was my attempt to get the headers. I just couldn’t get that to work. It seems that the output buffering gets in the way, and you can’t get to the headers until you flush the buffer.
But the second part is where you set the fallback Content-Type. I check to see if we’re generating a feed (is_feed()), then get the feed type from the query vars, and create an appropriate Content-Type from there.
Comment by Dougal Campbell — Tuesday 19/6/2007 @ 18:31
[…] plugins, then you probably already run the WP-Cache plugin (plugin directory, original announcment, recent security update info). Even though my site isn’t super busy, my server is a little light in the RAM department, and […]
Pingback by geek ramblings :: WP-Cache fix for Content-Type in feeds — Tuesday 19/6/2007 @ 18:57
Ricardo:
He activado tu plugin… tenia una version de hace como 2 años atras y funcionaba de maravilla… pero por alguna extraña razon esta version con la que viene el WP2 simplemente no hace nada.
Borre todo, baje el fix, luego lo active… y automaticamente ha creado sus directorios hace el link simbolico… pero hasta ahi.. no ha cachado ni una pagina en la ultima media hora con mas o menos 300 hits en el sitio. Tienes alguna idea del problema?
Saludos a todos, y gracias
Comment by Maski — Tuesday 19/6/2007 @ 19:49
[…] enabled WP-Cache (v 2.1.1). This should make loading pages — particularly long pages — quicker, and […]
Pingback by The Marmot’s Hole » WP Cache 2.1.1 — Friday 22/6/2007 @ 4:44
[…] Security Update - 2.1.1 […]
Pingback by Stop WP-Cache from caching the index page — Monday 25/6/2007 @ 16:07
Great work. Can I ask, Isn’t it about time you added compression features to wp-cache?
If the compression is on in the UI save both a plain and a gzip -9 version of the file and on a cache hit serve the correct version to the request?
One issue with this compression hack http://blog.iloaf.com/2007/03/15/make-wordpress-quicker/ is that is compresses each request.
TTFN & thanks again!
Comment by Chris — Friday 29/6/2007 @ 23:14
[…] to keep it interesting, I figured I’d better make sure I had the latest WP-Cache (2.1.1 as of this writing). While perusing the comments (I always read the comments about plugins!) I […]
Pingback by More Plugins and One Offs » Solo Technology — Friday 13/7/2007 @ 2:14
[…] domėtis WordPress tinklaraščius spartinančiomis priemonėmis. Viena tokių yra įskiepis WP-Cache 2.1.1. Ką jis daro? Jis po kiekvieno pasikeitimo sukuria statinius, nekintančius tinklaraščio […]
Pingback by Spartinančioji atmintis tinklaraščiams : nežinau.lt — Friday 13/7/2007 @ 17:01
[…] wieder hört man davon, dass man die WordPress-Performance steigern könne, wenn man das Plugin WP-Cache einsetzt. Viele vergessen allerdings dabei, auch auch WordPress eine durchaus akzeptable […]
Pingback by Bessere Blog-Performance dank WordPress-internen Cache — Software Guide — Friday 13/7/2007 @ 23:40
[…] WordPress-Plugin WP-Cache veranstaltet einige Probleme beim Einsatz. Dazu gibt es auf Software Guide einige Verbesserungen, […]
Pingback by DimidoBlog » Bloglinks der Woche 09.07.-15.07.2007 — Sunday 15/7/2007 @ 22:43
I’ve installed this plugin on several sites with success, but can’t get it fully working on one site. Have followed all instructions to the letter. The wp-content/cache directory IS filling up with cache files. But viewing source on generated pages the 2nd time, I never see the 2nd line telling me that I’m viewing a cached page. Have tried disabling all other plugins, have tried switching to default theme, have tried enabling and disabling wp-cache multiple times, but nothing works.
I’ve got it working on other blogs on the same PHP5 server. Is there anything else I can try to get this working? The only thing I can think of that’s different about this site is that it’s installed in a user home (has a ~ in the URL). Other than that, it’s vanilla. Weird.
Thanks,
Scot
Comment by Scot Hacker — Wednesday 18/7/2007 @ 2:42
[…] שמעוניין לנסות תוסף יעודי שעושה את זה מוזמן לבדוק את wp-cache אם כי אני מציע להיזהר משימוש בתוסף הזה על GoDaddy שכן אצלי […]
Pingback by The N.Z.B » להאיץ את וורדפרס — Friday 20/7/2007 @ 15:56
OK, I’ve solved this problem (comment #46), and wanted to leave a tip for others in the same boat. My usual method of making directories writable by the web server is this (assume user=username and www is the group the web server runs under:
drwxrwxr-x + 88 username www 2992 Jul 20 16:10 cache
In other words, directories are owned by the user, and in the group of the web server, and group write perms are enabled. It works for every situation I know of where a dir has to be web-server-writable, and this is how I set up wp-cache. But when I chmod 777′d the cache directory, the problem went away and wp-cache started working. I have NO idea why this is true, but there you go. This was on OS X Server with Apache 1.x and PHP 5.
Thanks,
Scot
Comment by Scot Hacker — Saturday 21/7/2007 @ 1:13